Information Disclosure in Confluence Data Center by Atlassian
CVE-2026-21579

8.2HIGH

Key Information:

Vendor

Atlassian

Vendor
CVE Published:
21 July 2026

What is CVE-2026-21579?

An information disclosure vulnerability affects multiple versions of Confluence Data Center, enabling unauthenticated attackers to access sensitive information. Affected versions include 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0. Atlassian recommends upgrading to the latest version or specific fixed versions to mitigate this risk. For safe operations, users are advised to check the release notes and ensure they are using a supported version.

Affected Version(s)

Confluence Data Center 10.2.0 to 10.2.13

Confluence Data Center 10.1.0 to 10.1.2

Confluence Data Center 10.0.2 to 10.0.3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.